A note before we begin. Last week, paid subscribers received Decoding Anthropic, an e-book that collects 11 essays I wrote on the company this year (PDF, 172 pages). While I originally planned to send it to all subscribers next month, I decided to release it this week in advance of the (possible!) publication of Anthropic’s S-1. You can find more details about the e-book's content in the post I sent last week. Paid subscribers will also receive the scoring of the actual S-1 against these essays when the prospectus becomes public.
Anthropic’s $2 trillion IPO case rests on more than model leadership. As frontier intelligence becomes cheaper and easier to substitute, the durable enterprise prize is the system of execution: the layer that captures organizational intent, carries authority through action, verifies results, retains context, and gets paid for accountable work.
TL;DR: The first AI disruption made software a tool. The second will make intelligence a tool. The company that survives both will own the continuity of the execution loop. In February, I wrote that Anthropic would have to become an enterprise software company. Six months later, that instruction is obsolete. Most software is still being disrupted; a few companies are mutating; and OpenAI has become an enterprise business converging on Anthropic’s buyer. Together they expose what the SaaSpocalypse hid: the unit that made enterprise software a category is dissolving, and what replaces it is not a system of action but a system of execution. A system of action stops at the recommendation: it still leaves a human to click, approve, or route. A system of execution closes the loop - the agent reasons, decides, and does, updating records, triggering workflows, resolving cases, under the same governance and permissions that once applied only to humans - and it answers for what happened, under whose authority, with what outcome, and gets paid for it. Anthropic already runs that loop in software, on the old units, and is an ingredient everywhere else. Weeks before an IPO expected to price at $2 trillion or more, the question is whether the coding loop generalizes to parts of the economy with no compiler, and what Anthropic will still own when Claude is no longer scarce.
Anthropic is reportedly seeking a $2 trillion valuation as it barrels toward a potentially record-setting IPO in October. Naturally, amid the current AI hype and hysteria, the instinct is to ask: Can such an astronomical valuation really be justified?
In that context, an investor asked me last week a rather audacious question about Anthropic’s potential valuation: What would an investor have to believe for a $3 trillion valuation to make sense?
The obvious place to start is the growth. Anthropic told investors it had reached a $65 billion run-rate by late July, according to Bloomberg. Preliminary second-quarter results showed more than $11.5 billion in revenue, with positive adjusted operating income, making it the first independent frontier lab to report an operating profit. OpenAI, meanwhile, told investors this month that its enterprise business now generates more revenue than its consumer business, with enterprise run-rate growing 50 percent quarter to date.
Those numbers explain why investors are asking the question. But they don’t answer it.
At $3 trillion, the question is what investors have to believe Anthropic ultimately becomes.
Six months ago, when Anthropic was valued at $380 billion, I argued that the answer was straightforward: it had to become an enterprise software company.
To win orchestration, I wrote in February, the frontier labs would have to pay “the expense of becoming an enterprise software company“ by acquiring all the things required to support the product: field sales, customer success, compliance certifications, and vertical domain expertise. Since then, Anthropic has done much of that. It has hired forward-deployed engineers, launched a roughly $1.5 billion enterprise-services venture with Blackstone and Goldman Sachs, rolled out Claude for Financial Services, introduced Claude for Legal, and landed deals with eight of the Fortune 10 enterprises.
And yet my original instruction may already be somewhat outdated. That’s not because Anthropic failed to follow it. But because enterprise software itself is no longer the destination.
The economic unit that defined the category for forty years was an application, sold by the seat, to a human who works inside its interface. That unit is fraying badly. Agents consume software without sitting in seats. They increasingly bypass the interfaces where humans once specified the work. And the systems of record underneath those interfaces are being recast as something more consequential: the authority layer against which autonomous work is permitted, executed, and verified.
Markets sense this, even if they cannot yet build a coherent thesis to explain it. The result can appear erratic to investors.
This month, Airtable, a $12 billion company at its 2021 peak, was sold for less than $1.3 billion. While Workday reported strong Q1 earnings in May, its stock is trading about 33% below its 2024 high. But it has also jumped 76% over the past month, including a boost since a report two weeks ago about a possible PE Buyout by Silver Lake that could have a broader impact on sector valuations.
As the old boundary around enterprise software dissolves, we can see three categories of competitors fighting to capture what is emerging to replace it.
The software incumbents are opening themselves to intelligence they do not own. Salesforce is exposing its records, workflows, and permissions to outside agents. Workday is rebuilding around Sana. At the same time, the frontier labs are moving in the opposite direction: outward from intelligence into applications, workflows, memory, permissions, and persistent agents. And then there are the AI-native, which begin with domain context, workflows, and the object around which the work is organized and are moving inward to acquire or build the intelligence they once rented.
That is what makes the $3 trillion question different from the $380 billion question I tried to answer in February. Back then, the challenge was whether Anthropic could move from supplying intelligence to orchestrating enterprise work. Now the harder question is what kind of company sits at the center of that work once intelligence itself becomes abundant, interchangeable, and progressively cheaper.
I have never seen Anthropic as a model provider with a plus sign attached. Across the eleven essays in my new e-book, “Decoding Anthropic,” the recurring argument is that the durable position sits above the model: in orchestration, context, and the ability to turn intelligence into useful work. But the changes now taking place across enterprise software suggest that even “enterprise software company” is no longer an adequate description of the destination.
What replaces it is not merely what the industry has started calling a system of action. A system of action answers: What should happen?
The more valuable layer answers a harder set of questions: What actually happened? Under whose authority? With what result? And who gets paid for it?
I call that layer the system of execution.
To elaborate on this concept, this essay makes four arguments.
First, the economic unit that made enterprise software a coherent category is dissolving, and the incumbents themselves are helping to dismantle it.
Second, what replaces it can be defined and tested: a system of execution owns the continuity between intent, authority, action, verification, and outcome.
Third, three species are now competing to control that loop: AI-native applications, software incumbents, and frontier labs. Each starts with a different piece and tries to acquire what it lacks.
And fourth, Anthropic presents the strangest case of all. In software development, Claude already participates in something close to the complete execution loop. Yet Anthropic owns neither the authoritative gates around that loop nor the economic unit by which its outcome is bought.
That is why the coming S-1 matters. It will inevitably be read as a growth story. It should also be read as a claim to ownership of the system-of-execution category that, despite Anthropic’s staggering rise over the past 18 months, the company has not captured yet.
Whether it’s $2 trillion or $3 trillion, investors have moved way beyond simply betting that Claude keeps getting smarter, or that Anthropic keeps growing. They are betting that Anthropic can turn intelligence into ownership of a layer that will remain scarce after intelligence itself no longer is. Yet even as the system of execution emerges as the biggest prize Anthropic is chasing, it is also exposing potential vulnerabilities that could derail its ascent.
How AI is breaking the enterprise software category
Enterprise software has not disappeared. Software spend is still growing at double digits.
What is dissolving is the economic definition that made it a category: an application, sold by the seat, to a human who works inside it. Those are the three legs I mapped in January, when Anthropic’s Cowork shipped.
In the last four months, all three have begun to change. And, crucially, the software incumbents themselves are doing much of the chopping to those three legs:
The seat. A seat priced the human doing the work, and revenue scaled with headcount because output did. When agents do the work, output decouples from headcount, and the seat stops being the primary unit of measurement. Investors now track consumption metrics: Salesforce's 3.8 billion Agentic Work Units a quarter, ServiceNow's billion dollars of AI contract value, Atlassian's Rovo-assisted actions. But for now, the transition is mid-flight with most of that consumption still billed through the seat.
The interface. The second leg is weakening even faster. The surface where intent met execution is being given away by the companies that built it because agents do not use it.
In January, I wrote that agents would bypass the UI moat because they execute through APIs, rather than screens. That prediction is now the incumbents’ own architecture.
Launching the new Slackbot in March, Salesforce Co-founder Parker Harris asked a question that would have sounded extraordinary coming from a SaaS company only a few years ago: “Why should you ever log into Salesforce again?” His own answer was “Maybe you never will. Maybe you will go into Slack.”
Two weeks later Salesforce CEO Marc Benioff compressed the strategy into five words: “Our API is the UI.”
As of late May (Q1 FY27 earnings), Salesforce now takes roughly a trillion API calls a quarter, has logged 4.5 million MCP calls into its platform in the six weeks after opening them, and put a million users on Slack’s MCP server in the same window. Its Agentforce experience layer renders the same logic into Slack, Teams, ChatGPT, Claude, or Gemini, whichever surface the customer chooses. Workday’s Sana replaces Workday’s menus and then runs inside Microsoft 365 Copilot. Microsoft has merged its consumer and enterprise Copilots into one app whose background agents act on Graph signals without being asked.
The interface has not disappeared. But it has stopped being the place where the work is specified.
That matters because the company that owns the screen no longer necessarily owns the user’s intent. And once intent originates somewhere else, the interface ceases to be the natural center of the execution loop.
The record. This is where I need to make the biggest amendment to my February argument. I wrote then that systems of record had to become systems of action, the brain that tells the agent what to do or risk being “priced like a database.”
I was right about the position and wrong about the price.
The system of record is not being demoted to a database. It is being promoted to the trust boundary: the authoritative substrate against which autonomous work is authorized and verified.
An agent may decide what ought to happen. But when it attempts to change a payroll record, transfer money, update a customer account, approve an employee action, or trigger a regulated workflow, it still must cross the permissions and business rules of the authoritative system underneath it.
Industry analyst Josh Bersin described Workday’s architecture like this: “when the agent needs to interact with people, money, or regulated workflow, the reasoning hands off to Workday for that portion of the execution.”
That goes beyond what a passive database does. It stakes a claim on the boundary every autonomous agent eventually has to cross: who has the authority to make an action real?
So, the record survives. If anything, it becomes more strategically important once the interface above it disappears. The open question is whether controlling that trust boundary also means capturing the economic rent.
And that is what makes Salesforce and other incumbent systems of record potentially more dangerous to Anthropic, not less.
The system of execution
Enterprise software categories have historically been defined by the scarce asset they controlled.
Geoffrey Moore’s systems of record owned canonical state: the authoritative answer to what is true? His systems of engagement owned the session through which people interacted with that state. Jerry Chen’s systems of intelligence owned the prediction derived from it.
Each transition moved the scarce asset one layer higher.
Proposed successors have included candidates such as ServiceNow’s system of action and Oracle’s “system of outcomes”. They define the next category by what it does.
But behavior alone is not a moat.
That is the lesson the Red Queen taught us in June: behavior is increasingly expressed in code, and code diffuses. If one agent can reason, plan, call tools, and execute a workflow, many agents will eventually. As intelligence and agency become abundant, neither reasoning nor action by itself remains the scarce asset.
Oracle’s noun gets closer: the outcome:
But even an outcome is something a system produces. It does not tell us who controlled the chain that produced it, whether the action was authorized, how the result was verified, or who can claim it economically.
That chain is the scarce asset. So, as we have done in the past, we should name the category by what it owns, and not by the behavior.
This is why I have chosen to call it the system of execution: the layer that owns the continuity between organizational intent and a verified result. It captures what the organization wants done, carries the authority to perform the work, preserves the context required to do it, executes across underlying systems, verifies what happened, retains the accountable history, and learns from the result.
The critical asset is not any individual step. It is continuity across the loop. A company does not need to own every database, model, or application the work passes through. But it must remain the layer that keeps execution coherent as intent becomes action, and action becomes an accountable result.
By framing the system of execution in this way, it gives the category two distinct tests:
The first is position. Does the system capture the intent? Does it hold or enforce the authority under which the action occurs? Does it preserve the relevant context? Does it retain the verified history for what happened?
The second is economics. Can it turn that accountable work into the unit that earns revenue?
A company can participate deeply in execution without satisfying both tests. It can perform the work while borrowing another system’s authority. It can control the workflow while charging by the seat. It can verify an action without capturing the economic value of the result.
That distinction matters. Being inside the execution loop is not the same thing as owning it. So, the progression looks like this:
Execution = action + authority + verification + accountability + economic settlement.
Position: capture the intent · hold or delegate authority · preserve the context · retain the verified history.
Economics: the outcome is the unit of account · revenue follows the outcome, not the input.
System of record: What is true? System of action: What should happen? System of execution: What happened, under whose authority, with what result?
The system of record owns the truth. The system of execution owns the receipt. The receipt is the accountable evidence that work occurred: what was requested, what authority permitted it, what actions were taken, what changed, and whether the result was verified.
That is why a model alone cannot own this category. The model can reason about the work and increasingly perform the work. But the model does not, by itself, possess the authority, organizational context, verification layer, or durable history that turns an action into an accountable execution.
And the receipt has an economic implication.
Enterprise software traditionally charged for the input into work: the seat, the session, the hour, the token. A mature system of execution should increasingly charge for the accountable work itself.
That does not mean every workflow suddenly becomes pure outcome pricing. The transition will be messy, and hybrids will persist for years. But the economic direction matters: the closer the provider gets to owning a verified result, the less natural it becomes to price the intelligence consumed along the way.
Salesforce’s Agentic Work Units illustrate the gap. They measure machine activity inside the system. But an action count is not yet the same thing as an economically settled outcome. The category becomes more valuable as the receipt itself becomes something customers are willing to buy.

This also clarifies the relationship between the execution system and the layers beneath it.
The model is an input. Increasingly, it should be replaceable without breaking the continuity of the work. Harvey is already demonstrating the principle: it has changed its model mix repeatedly while preserving the matter, its context and its workflow. The intelligence can change while the object of work survives.
The system of record is different. It is the authoritative substrate against which execution is permitted and to which execution writes. The system of execution does not have to own that record, but it cannot simply ignore it. Every consequential autonomous action eventually has to encounter some source of authority and truth.
The durable layer therefore sits between them: above increasingly interchangeable intelligence, but across the systems of record that still hold organizational authority.
In the vocabulary of the Manifesto, this is the orchestrator with an economic unit attached. Intent originates at organizational scale rather than in a prompt box. Authority determines which actions are actually permitted. Context compounds across tasks and model generations. Verification converts activity into accountable work. The economic unit shifts from resources consumed to results produced.
When Claude Managed Agents introduced the session-hour in April, I argued that the hour was effectively a headcount metric: synthetic colleagues competing for labor budgets. But companies do not ultimately buy hours because they want hours. They buy what those hours accomplish.
That gives us a way to test the category rather than merely name it. A candidate does not control the execution position if organizational intent is formed somewhere else and merely arrives as an instruction; if authority remains entirely outside the product; if its memory and execution history walk away at negligible cost; or if it cannot verify, refuse, escalate, or reverse consequential actions.
And it has not captured the execution economics if its revenue still rises primarily with the inputs consumed - seats, hours or tokens - rather than with the accountable work produced.
That is the test the next generation of enterprise companies will have to pass.
The question is no longer simply who can make the agent act? It is who owns the continuity that makes the action authorized, verifiable, accountable, and economically theirs?
Three species competing for the execution loop
Three species are competing to own the execution, approaching it from different starting positions:
The AI-natives start with the work and acquire intelligence.
The incumbents start with state and authority and acquire intelligence.
The labs start with intelligence and must acquire organizational authority and context
Each begins with one scarce asset and must acquire the others without surrendering the economic rent to the layer it depends on.
The AI-natives start: with the work
Harvey is the clearest specimen of the species, though not yet of the category. In February I called it a wrapper with "minimal switching costs," and at the time I think that was fair: a workflow layer on rented models. What it has built since is the escape from that description - a permissioned object of work that survives a change of model. The escape is unfinished but the direction is interesting.
Harvey II, shipped on August 18, is organized around a permissioned object of work: the Space. In legal worlds, that object is critical. The Space holds the documents, parties, tasks, and history associated with it. The firm’s ethical walls sync in from existing systems such as Intapp. Harvey’s memory of how each lawyer works follows that lawyer across Harvey, Word, and Outlook. Shared workspaces allow clients to work inside the same object.
This matters because Harvey is no longer merely inserting intelligence into somebody else’s workflow. It is trying to become the place where the work itself persists. Intent originates there. Context accumulates there. Permissions are enforced there. The model can change without the matter disappearing.
Having built that side of the loop, Harvey is now acquiring the other one: intelligence.
Alongside Harvey II, it announced Tenet, its first model, post-trained on Moonshot’s open-weight Kimi K3. Harvey says Tenet reaches frontier-level performance on its own benchmarks at “an open-source cost,” which Harvey says makes “it practical to run agents continuously across every matter”, with a firm-knowledge research model alongside it at 90% less per query.

Harvey did not do this because Claude was too weak. Claude Fable 5 scores 93.4% on Harvey’s BigLaw Bench, and on the agentic benchmark Tenet was trained against, no frontier model passes more than about 14% of tasks end to end.
The problem Harvey is trying to solve is cost and horizon.
A continuously running agent on a legal matter becomes difficult to sustain if every additional action is priced at frontier-model rates. And if Harvey eventually wants to charge for completed work rather than seats, it cannot allow the inference cost underneath that work to remain outside its control. So Harvey is moving down the stack.
It still does not own the canonical matter record, which remains in systems such as iManage or NetDocuments. It borrows parts of the permission structure from Intapp. And most of its revenue still comes from seats rather than outcomes.
But the strategic direction is clear: Harvey started with the work, rented the intelligence, and is now beginning to manufacture its own.
The incumbents: start with authority
Salesforce is making the opposite bet.
It begins with what Harvey and the labs do not have: customer data, business rules, workflows, permissions, and a long-lived organizational record.
With Headless 360 and the MCP servers it has added around the core platform and Data 360, Salesforce is exposing those assets to agents whose reasoning loop may run somewhere else. An external agent can act as an authenticated user inside the organization’s existing permissions.
Salesforce is therefore conceding something that once looked fundamental: the interface.
Rohan Kumar, its platform chief, has said the company is “not locking these APIs down to only Salesforce.” Marc Benioff has made the strategic logic even clearer: agents may reason elsewhere, but they still need to “phone home” to the system that knows the customer, the pipeline, the org chart and the permissions.
The prompt box is surrendered. The authority boundary is defended.
Slack Code is the interface half of the same bet. A user can summon Claude, Devin, GitHub Copilot or another coding agent from a Slack conversation. The channel then becomes where the organization sees the plan, reviews the diffs, routes approvals, and follows the work toward a merged pull request.
Slack is not trying to own the model. It is trying to own the venue in which organizational intent becomes coordinated work. That puts it directly in competition with Anthropic’s own attempts to move upstream from the individual developer into the team.
Salesforce’s advantage is therefore not intelligence. It is that the agent must eventually cross a boundary Salesforce already controls.
Put the two halves together and the shape of the bet is visible. With Headless 360, Salesforce owns the boundary an agent must cross to commit an action; with Slack, it owns the venue where the organization's intent forms and the work is watched, approved, and archived. That is two gates of the execution loop - the first and the last that matter - without owning the reasoning that runs between them. It is a toll position, and it compounds: every agent the enterprise adds is another crosser at both gates.
Workday is pursuing a similar strategy. Sana can become the user’s front door, even inside Microsoft 365 Copilot, while consequential actions still return to Workday’s approval and policy layer.
The incumbent bet can therefore be stated simply: Let the intelligence come from anywhere. Make every consequential action come home.
The labs: start with intelligence
The frontier labs begin with the asset the other two species are trying to acquire.
They own the frontier, the harness that decomposes and delegates, and the individual’s intent at the scale of a billion users, Gemini’s and ChatGPT’s.
What they lack is organizational authority and the permissioned object of work. In February I described the two bets: OpenAI’s Frontier, still in limited rollout, a control plane above all agents with identities that carry scoped permissions; and Anthropic’s vertical bet, building outward from the agent, Claude Code to Cowork to Managed Agents.
Both are in the contest. Neither has the customer’s identity provider delegating to it yet.
| Species | Starts with | Must acquire |
| ------------- | --------------------- | ---------------------------------- |
| AI-native | Work + domain context | Cheap, controllable intelligence |
| Incumbent | State + authority | Intelligence |
| Lab. | Intelligence | Organizational authority + context |
Figure 2. Three species competing for the execution loop. Source: Decoding Discontinuity analysis, August 2026.
Looking across this chart reveals an asymmetry in the three-species race.
The incumbents are trying to acquire intelligence, whose price is falling and whose supply is expanding. The labs are trying to acquire authority, organizational context, and institutional trust, which are slower to build and harder to substitute.
Early evidence now suggests enterprises are already behaving this way. A Financial Times analysis of Ramp spending data from 70,000 companies found that Fable 5, Anthropic’s most capable and expensive model, had plateaued at only about 11% of customer spending more than two months after launch. Anthropic’s cheaper Opus 5 surpassed it within weeks. As Accel’s Miles Clements, an Anthropic investor, put it: “Most people don’t need to operate at the frontier.”
That matters because it is the economic assumption underneath this entire contest. If customers increasingly route ordinary work toward the cheapest model capable of completing it, intelligence does not have to become literally commoditized for its strategic value to decline. It only has to become sufficiently substitutable.
The AI-natives already own the work and the domain context, but they must acquire enough intelligence to make that work economically viable while defending the workflow from being absorbed by the model provider or the incumbent system of record.
Look at Claude Code
Anthropic calls Claude an “intelligence platform” and sells a “Claude Platform”. But it has not yet named the category it is ultimately trying to own. That is striking because many of the pieces are already there.
Managed Agents provides a runtime with state and permissioning. The memory architecture exposed in March showed how far Anthropic is thinking beyond the prompt. Claude Tag moves Claude into the organizational channel. The session-hour was an early attempt to move the unit of account beyond the token. Anthropic has been assembling the organs of an execution system without calling it one.
And in the domain of software, we can already see what the completed loop looks like:
Intent - the Slack thread, the IDE, the terminal
Context - the repository and the memory of how the team works
Authority - GitHub, CI, merge permissions
Action - code
Verification - the compiler, the tests, the pull request
Outcome - deployed software
Learning - the next task
Coding is unusual because almost every link in that chain is already machine-readable. The verifier is cheap, fast, and general-purpose. Tests either pass or fail. The compiler accepts the code or rejects it. Git records the changes. The pull request provides an auditable object around the work. That makes software the first major general-purpose knowledge-work domain in which an AI agent can approach the complete execution loop without first inventing the verification infrastructure around it. And Claude Code demonstrates how powerful that position can be.
But it also exposes the limitation.
Anthropic may perform much of the work, but it does not own several of the gates that make the work authoritative. GitHub controls critical permissions and the merge. The customer owns the tests and ultimately decides what counts as a valid result. And Anthropic still gets paid largely through old units: seats and tokens.
This distinction is important. Claude Code occupies the execution loop. Anthropic does not yet own the continuity of that loop.
That is why Claude Code is such an important proof point. Anthropic no longer has to prove that its intelligence can perform consequential work over long horizons. In coding, it already can.
What it has to prove is that this capability can become a durable position - and then a durable economic position - before the intelligence underneath it becomes interchangeable.
That is also why the competitive attacks are moving upstream.
Slack Code and shared Copilot sessions inside Teams are not primarily attacks on the terminal. They aim to capture the point where the organization specifies the work.
The developer may choose the agent. But if the task originates in Slack, permissions come from GitHub, verification comes from the customer’s CI system, and the organization observes the result somewhere other than Claude, Anthropic risks becoming the most capable participant in a loop whose continuity belongs to somebody else.
That is the central lesson from Claude Code: proof of capability is not proof of category ownership.
There is an early warning that this distinction may already matter.
One third-party tracker, anchored to Anthropic’s own February disclosure and read as an estimate, suggested Claude Code’s tracked run-rate has flattened since mid-June even as the rest of Anthropic continued to grow, and OpenAI’s Codex accelerated. Important qualifications remain: the tracker cannot see spending migrating into Claude Tag, Cowork, and Managed Agents, and Microsoft’s cancellation of thousands of internal Claude Code seats at the end of June distorted the comparison.
So, this is not conclusive evidence. But the timing is notable. The slowdown arrived just as Slack, Teams, and GitHub were pushing further upstream into the organizational workflow. If that pattern persists, it would suggest that owning the agent is not enough when somebody else owns where the work begins and where it becomes authoritative.
And this brings us to the harder problem: Most of the economy does not have a compiler.
Legal has partners, judges, and client review. Finance has reconciliations and ledgers. HR has policy and approvals. Sales has revenue. Operations has physical outcomes.
Each domain has a verifier. But those verifiers are slower, messier, and more contextual than a compiler or test suite. They depend on institutional rules, human judgment, and systems of record that already belong to somebody.
That helps explain why legal is emerging as the first credible non-code domain for AI-native execution systems. The legal matter was already a permissioned object of work before the agent arrived. Harvey did not have to invent that unit from scratch.
Other domains are harder. And that reframes the Anthropic valuation question.
The question is not whether Claude will be intelligent enough to reason about finance, HR, sales or operations. It almost certainly will.
The question is whether Anthropic can acquire the intent, context, authority and verification architecture around that intelligence before the companies that already own those assets acquire intelligence of their own.
Anthropic’s $2 trillion question
That architecture has four parts, and you have to believe in all of them.
That Anthropic can capture the organization’s intent. Individual intent is largely won at the labs’ scale, though Anthropic’s consumer base is a fraction of OpenAI’s or Google’s. The organization’s intent is contested, and Anthropic has no venue of its own; Claude Tag is a guest in Slack’s channel, Claude Code a guest in Slack Code: the interface risk I named in May, with a date on it.
That the context compounds and does not walk. The orchestrator’s context is not the record; it is the meta-context, the routing memory and cross-system relationships no single system of record can see. But it is months old against records that are decades old, held per user or per channel rather than as the organization’s shared, permissioned memory. Microsoft’s Work IQ is the latter; Microsoft’s own framing of Opus 5 in Copilot was Claude “combined with Work IQ”. Unproven at organizational scale, and the most buildable of the four.
That Anthropic can hold authority, not just borrow it. This is the real bottleneck, and it is harder than it looks. Every time a Claude agent acts inside Salesforce, Slack, or GitHub, it acts under the user’s permissions in that system, enforced by that system. “Phone home” is not a bug; it is the trust boundary the customer already bought. Harvey borrows its walls from Intapp the same way; what it has that Anthropic lacks is a Space that enforces the borrowed walls on every agent action, a durable principal the customer administers inside the product. Building that, a standing agent identity the customer’s identity provider delegates to, is a multi-year identity, governance, and legal product, not a feature. Claude Tag has an identity in the channel, and Frontier has agent identities on paper, but none yet is the object the customer’s identity provider delegates to. Until that flips, the lab is a very good executor, not a system of execution.
Anthropic can get paid for the outcome rather than the token. By third-party estimates, roughly three-quarters of revenue is API and enterprise usage, and Claude Code itself is sold by the seat; Anthropic has not disclosed the mix. Dario Amodei has said the industry will see “pay for results” in some form, and Sierra already bills per outcome. The problem is deeper than packaging. A system of execution is a token-minimizing business; Harvey’s firm-knowledge model, at 90 percent less per query, is what that looks like. Anthropic has reserved compute on a scale without precedent: my reconstruction two weeks ago put its announced commitments at roughly $254 billion, rising toward $454 billion if an unconfirmed Google figure is included, on terms that are not public.
A balance sheet built on reserved capacity is structurally long token volume, and an outcome-priced business is indifferent to it; the conflict is between the balance sheet and the business model. Harvey can make the move because it already routes routine work to models it owns; Anthropic’s commitments make it far more expensive. Outcome pricing will arrive layered on top of usage revenue; the multiple will live with that hybrid for years.
Three end-states follow. The first is the software position generalized and repriced: a venue for the organization’s intent, a shared memory with entitlements, a delegated-authority object, outcome-priced lines on Managed Agents. That is what $2 trillion prices. The second is the frontier ingredient beneath everyone else’s system of execution, supplying cognition on a deflating meter: the tax collector of digital labor I described in April, a high-growth utility that does not clear the bar. The third is the Red Queen with a balance sheet.
For the first to be priceable, the S-1 has to let investors reconstruct five things: revenue split between tokens, seats, session-hours, outcome-priced work, and services; the channel mix, intent initiated in Anthropic’s own surfaces versus in someone else’s venue; any organization-level memory or entitlements product; the purchase-obligation footnote, firm versus cancellable; and the trend in inference cost per verified outcome, not per token. Everything else is noise.
Recursive self-improvement and the execution moat
This has to be settled now. In June, I argued that recursive self-improvement is the seventh tremor: it accelerates the commoditization of intelligence, perfects the harness, and leaves the durable surplus in the one ring with no in-silico scorer or operational context.
A week later, Fable showed that the frontier itself can be switched off by a letter, and that the companies which fell back to the previous model did not get worse answers; their long-horizon workflows simply stopped clearing. The argument does not require the loop to close next year, only that investors can no longer value it away. If self-improvement makes intelligence the fastest-depreciating component in the stack, then a company built around intelligence is structurally unstable. The better intelligence becomes, the less differentiated intelligence itself is.
Anthropic could win the frontier and still lose the economics. The observable is not a benchmark: for a fixed task, the price gap between the frontier model and the open-weight model that is good enough, and the direction it moves.
The model is not the destination. It is the intelligence layer inside the next system. And the question every investor at $2 trillion should be asking is which company owns the layer that remains scarce when intelligence itself stops being scarce.
At the same time, RSI is what could accelerate Anthropic’s position.
Who owns the execution loop?
The scarce thing after intelligence is not the ability to act. It is the ability to make action accountable, to authority, to outcome, and ultimately to an economic unit. The winner is the layer that can turn that accountable outcome into the unit on which the work is bought: not the smartest model, but whoever owns the continuity of the loop, intent, authority, execution, verification, outcome, learning, and is paid for the outcome.
Harvey owns the workspace around the matter. Salesforce owns the action boundary. Anthropic owns the intelligence, and, in software, the position. The contest is who extends their side of the loop across the other two before the intelligence in the middle of it becomes a commodity.
At $2 trillion (or even $3 trillion?), investors are not buying Claude. They are buying the assumption that Claude will still own something when Claude is no longer scarce.
If that something is intelligence, the valuation depends on a frontier monopoly that may not last. If that something is execution, Anthropic has to acquire authority, organizational intent, and the verified history of work before somebody else does.
That is the $2 trillion question. Not whether Anthropic wins the intelligence race. Whether it owns the receipt when intelligence is no longer scarce.
DISCLAIMER: The views and opinions expressed here are those of the author alone and are based on publicly available information. They do not constitute investment advice, a solicitation, or a recommendation to buy or sell any security or financial instrument. The author may hold positions in the securities of companies mentioned. The author may be an advisor to some of the companies mentioned in this article. Past performance is not indicative of future results. Readers should conduct their own independent due diligence and consult a qualified financial advisor before making any investment decision.






